Medisure Cyber Risk Assessment
& Underwriting Agreement
Overview
This Agreement outlines the services Medisure provides, the responsibilities of both parties, and the terms governing our cyber risk assessment and underwriting support process. Please review the information below and sign electronically using the secure HIPAATIZER form.
1. Parties
This Cyber Risk Assessment & Underwriting Agreement (“Agreement”) is entered into between:
Medisure LLC, a Texas limited liability company (“Consultant”), and Client (“Customer”).
Both parties agree to the terms below and acknowledge that electronic signatures executed through the Wix Signature Block constitute legally binding signatures under Texas law.
2. Purpose of Agreement
The purpose of this Agreement is to define the scope, responsibilities, fees, and legal terms governing Medisure’s cyber risk assessment and underwriting support services for Customer’s organization.
3. Services Included
3.1 Cyber Risk Assessment
Consultant will perform a structured cyber risk assessment tailored to small and mid‑sized healthcare practices. Assessment activities include:
-
Evaluation of administrative, technical, and physical security controls
-
Review of MFA enforcement, endpoint protection, backup configurations, firewall settings, and training records
-
Identification of gaps affecting insurability or underwriting outcomes
-
Documentation of findings in a carrier‑ready format
3.2 Evidence Review
Consultant will review evidence provided by Customer or Customer’s MSP/IT provider. Evidence may include:
-
Security configurations
-
Policy documentation
-
Logs, reports, or screenshots
-
MSP attestations
3.3 Underwriting Preparation
Consultant will prepare a complete underwriting package including:
-
Assessment findings
-
Security posture summary
-
Carrier‑aligned documentation
-
Clarifications for brokers or carriers
3.4 Carrier Submission Support
Consultant will support Customer’s broker by:
-
Responding to carrier questions
-
Providing supplemental documentation
-
Clarifying technical details
4. Exclusions
The following services are not included:
-
Technical remediation, patching, configuration changes, or deployment of security tools
-
MSP or IT management services
-
Legal, regulatory, or compliance advice
-
Incident response or forensic investigation
-
Guarantee of carrier approval, pricing, or coverage
5. Fees & Payment Terms
-
Total Fee: As quoted
-
Deposit: 50% due upon signing
-
Final Payment: 50% due upon delivery of underwriting package
-
Payments are processed through Stripe
-
Fees are non‑refundable once work begins
6. Customer Responsibilities
Customer agrees to:
-
Provide accurate business and technical information
-
Provide MSP contact details
-
Provide requested evidence promptly
-
Respond to follow‑up questions during assessment
-
Disclose any cyber incidents within the last 5 years
Failure to provide timely information may delay project timelines.
7. Timeline
Typical project timeline:
-
Intake & evidence collection: 1–2 weeks
-
Cyber risk assessment: 1 week
-
Underwriting preparation: 1 week
Timeline may vary based on responsiveness and evidence availability.
8. Confidentiality
Both parties agree to maintain the confidentiality of all shared information. Consultant will not disclose Customer’s information except:
-
To Customer’s broker for underwriting purposes
-
As required by law
-
With Customer’s written consent
9. Limitation of Liability
Consultant provides advisory services only. Consultant is not liable for:
-
Carrier decisions, pricing, or coverage outcomes
-
MSP actions or omissions
-
Third‑party vendor failures
-
Cyber incidents occurring before, during, or after the engagement
Liability is limited to the total fees paid under this Agreement.
10. Indemnification (Texas‑Specific)
Customer agrees to indemnify, defend, and hold harmless Consultant, its members, employees, and contractors from and against any claims, damages, losses, liabilities, costs, or expenses (including reasonable attorney’s fees) arising out of:
-
Customer’s failure to implement recommended security controls
-
Customer’s misrepresentation or omission of material information
-
Actions or omissions of Customer’s MSP, IT provider, or third‑party vendors
-
Any cyber incident occurring within Customer’s environment
Consultant agrees to indemnify Customer only for claims arising from Consultant’s gross negligence or willful misconduct, as defined under Texas law.
11. Arbitration Clause (Texas‑Specific)
Any dispute, claim, or controversy arising out of or relating to this Agreement shall be resolved exclusively through binding arbitration administered in accordance with the Texas Arbitration Act (Texas Civil Practice & Remedies Code §171).
11.1 Arbitration Terms
Venue: Collin County, Texas
Arbitrator: A single neutral arbitrator mutually agreed upon
Governing Rules: Texas Arbitration Act
Costs: Each party bears its own legal fees; arbitration costs split equally
Judgment: Arbitrator’s decision may be entered in any court of competent jurisdiction
11.2 Waiver of Jury Trial
Both parties knowingly and voluntarily waive any right to a jury trial.
11.3 Exception
Either party may seek temporary injunctive relief in a Texas court to protect confidential information or intellectual property.
12. Governing Law
This Agreement is governed by the laws of the State of Texas, without regard to conflict‑of‑law principles.
11. Electronic Signatures (Texas UETA & ESIGN Compliance)
Customer and Consultant agree that:
-
Signatures executed through the Wix Signature Block constitute legally binding electronic signatures
-
This Agreement may be signed electronically and stored digitally
-
Electronic signatures have the same legal effect as handwritten signatures under:
-
Texas Business & Commerce Code Chapter 322 (UETA)
-
Federal ESIGN Act (15 U.S.C. § 7001)
-
13. Electronic Signatures (Texas UETA & ESIGN Compliance)
Both parties agree that:
-
Signatures executed through the Wix Signature Block are legally binding
-
Electronic signatures have the same legal effect as handwritten signatures under:
-
Texas Business & Commerce Code Chapter 322 (UETA)
-
Federal ESIGN Act (15 U.S.C. § 7001)
-
14. Entire Agreement
This Agreement constitutes the entire understanding between the parties and supersedes all prior discussions or agreements. Amendments must be in writing and signed by both parties.
15. Next Steps After Signing
Once the Agreement is signed:
-
Stripe will send Invoice #1 (50% deposit)
-
You will receive your Cyber Intake Form
-
Evidence collection begins
-
Medisure completes your assessment and underwriting package
_edited_edited_edited.png)